dNs BiT 0x20 EnCoDiNg

This is going to make you chuckle… there’s a security feature for dnsmasq called ‘DNS bit 0x20 encoding’ (ie: mixed case query randomization)… it randomizes the case of each DNS query, and only accepts the answer back from the upstream DNS server if the case exactly equals that randomization.

Add the flag to the /etc/config/dhcp → config dnsmasq block:

uci set dhcp.@dnsmasq[0].extraconftext="do-0x20-encode"

That gets put into /etc/config/dhcp, under the config dnsmasq block as:

option extraconftext 'do-0x20-encode'

Commit the configuration change:

uci commit dhcp

Restart dnsmasq to apply it:

/etc/init.d/dnsmasq restart

Make sure it’s working:

tcpdump -i lo -vvv -A udp port 5053

NOTE: The above requires the tcpdump package be installed.

NOTE: The above assumes you’re using the https-dns-proxy setup. If not, change ‘5053’ to ‘53’ or whatever port you’re using for DNS.

If it’s working, you’ll see something like this:

21:03:43.063237 IP (tos 0x0, ttl 127, id 48117, offset 0, flags [DF], proto UDP (17), length 71) localhost.58981 > localhost.5053: [bad udp cksum 0xfe46 → 0xc9c1!] UDP, length 43 E…G…@…A…e…3.F…wWW.goOgLE.CoM…A…)…

21:03:43.217356 IP (tos 0x0, ttl 127, id 48136, offset 0, flags [DF], proto UDP (17), length 110) localhost.5053 > localhost.58981: [bad udp cksum 0xfe6d → 0xa8c8!] UDP, length 82 E…n…@…At…e.Z.m…wWW.goOgLE.CoM…A…www.google.com…A…h2.h3…)…

21:04:19.744708 IP (tos 0x0, ttl 127, id 50319, offset 0, flags [DF], proto UDP (17), length 77) localhost.61367 > localhost.5053: [bad udp cksum 0xfe4c → 0xe024!] UDP, length 49 E…M…@…9…9.L…gATEway.FaceBoOk.cOm…)…

21:04:19.938024 IP (tos 0x0, ttl 127, id 50338, offset 0, flags [DF], proto UDP (17), length 148) localhost.5053 > localhost.61367: [bad udp cksum 0xfe93 → 0x53f3!] UDP, length 120 E…@…8…gATEway.FaceBoOk.cOm…gateway.facebook.com…[…dgw.c10r…F…[…*.(…b…)…